Date: Thu, 2 Aug 2012 02:27:38 -0300
From: LinkedIn Password [password@linkedin.com]
Subject: Reset Your LinkedIn Password
Hi altera,
Can’t remember your LinkedIn password? No problem - it happens.
Please use this link to reset your password within the next 1 day:
Click here
Then sign in to LinkedIn with your new password and the email address where you received this message.
Thanks for using LinkedIn!
Flaws in SQL server implementations are a hacker's favourite target, so perhaps there is a wry sense of humour here. Anyway, the malicious payload is at [donotclick]mysqlfordummys.ru:8080/forum/showthread.php?page=5fa58bce769e5c2c (report here) hosted on 203.80.16.81 (MYREN Infrastructure, Malaysia)
The following domains and IPs are all related, you should block access to them if you can:
ipadvssonyx.ru
mysqlfordummys.ru
onerussiaboard.ru
online-cammunity.ru
online-gaminatore.ru
switched-games.ru
zenedin-zidane.ru
41.66.137.155
41.168.5.140
62.76.188.138
62.76.190.208
62.213.64.161
78.83.233.242
85.143.166.243
87.120.41.155
87.204.199.100
173.224.208.60
184.106.189.124
199.71.212.78
203.80.16.81
203.172.140.202
No comments:
Post a Comment